procmail¿¡¼ Swen ¿ú ÇÊÅ͸µ | ÀÛ¼ºÀÏ : 2003/09/21 18:55 |
Á¶È¸¼ö : 6570 |
ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ ) ÀÛ¼ºÀÏ : 2003.9.21(ÀÏ) Swen ¿ú(Win32.Swen@mm.worm, ½ºÀ¢ ¿ú)ÀÌ ±¹³»¿¡µµ µé¾î¿Ô´Ù°í Çϴµ¥, ¾ÆÁ÷ ¹Þ¾Æº¸Áö ¸øÇß½À´Ï´Ù. µû¶ó¼ ¾Æ·¡ ¼³Á¤À» Å×½ºÆ®´Â ¸øÇß½À´Ï´Ù. ¹Ì¸® ÁغñÇÑ´Ù°í ¼ÕÇغ¼ °Íµµ ¾ø°ÚÁÒ? Swen¿úÀÌ ¸ÞÀϷθ¸ ÀüÆĵǴ °ÍÀÌ ¾Æ´Ï°í KaZaA P2P ÇÁ·Î±×·¥°ú IRC(mIRC ÀÌ¿ë), °øÀ¯µÈ ³×Æ®¿öÅ© Æú´õ¸¦ ÅëÇؼµµ ÀüÆĵ˴ϴÙ. ´ÙÀ½Àº ¿Ü±¹ÀÇ ÇÑ ´º½º±×·ì¿¡ Æ÷½ºÆõƴø ÇÊÅ͸µ ¼³Á¤ÀÔ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 11ÁÙ) /etc/procmailrc ¿¡ Ãß°¡ÇÏ¸é µË´Ï´Ù. -------------------------------------------------- SPAM_LOG = "/var/log/spam.log" :0 * > 140000 * < 165000 { :0 BD * b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv $SPAM_LOG } -------------------------------------------------- ¸ÞÀÏ Å©±â°¡ 140K~165KÀÌ°í, º»¹®¿¡ b3I... °¡ Æ÷ÇÔµÈ °ÍÀº Swen ¿úÀ¸·Î °£ÁÖÇÏ¿© $SPAM_LOG¿¡ ÀúÀåÇصӴϴÙ. ¿úÀ» ÀúÀåÇØ µÑ ÇÊ¿ä¾øÀ¸¸é $SPAM_LOG ´ë½Å¿¡ /dev/null·Î. Swen ¿úÀÌ Á¦¸ñÀ̳ª ÷ºÎÆÄÀϸíÀÌ ÀÏÁ¤ÇÏÁö ¾Ê±â ¶§¹®¿¡ Àú·± Çü½ÄÀ¸·Î ÇÊÅ͸µÇÕ´Ï´Ù¸¸ ÇÑ°¡Áö ´Ù¸¥ Ư¡ Áß¿¡ 'subject:'ÀÌ ´ë¹®ÀÚ¶ø´Ï´Ù. µû¶ó¼ ´ÙÀ½°ú °°Àº ÇüÅ·εµ °¡´ÉÇÕ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 5ÁÙ) -------------------------------------------------- SPAM_LOG = "/var/log/spam.log" :0 D * ^SUBJECT: $SPAM_LOG -------------------------------------------------- Swen ¿úÀÇ »ó¼¼ÇÑ Á¤º¸´Â http://www.certcc.or.kr/cvirc/Alert/warning/2003/W32_Swen@mm_worm.html http://home.ahnlab.com/smart2u/virus_detail_1220.html |
Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ / URL : http://coffeenix.net/board_view.php?bd_code=75 |